ZeroHour

CVE-2020-9934

KEVmass

Environment Variable Handling Information Disclosure in Apple iOS, iPadOS, and macOS

CISA: Apple iOS, iPadOS, and macOS Input Validation Vulnerability

CVSS 3.1
5.5 medium
EPSS
3%p87
Published
()
KEV added
AI analysis

CVE-2020-9934 is an input validation flaw in the way Apple operating systems handled environment variables, which could allow a local user to view sensitive user information. It is triggered by a local attacker or user with limited privileges running code or commands on a vulnerable device, where the mishandled environment variables leak data. Successful exploitation results in disclosure of confidential information only, with no impact on data integrity or availability per the CVSS scoring. It affects devices running iOS or iPadOS versions before 13.6 and macOS Catalina versions before 10.15.6. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-08, confirming exploitation in the wild, though no public proof-of-concept is known.

What to do: Upgrade affected devices to iOS 13.6 / iPadOS 13.6 or later, and macOS Catalina systems to 10.15.6 or later, as required by CISA's KEV listing. Because exploitation requires local access, restrict local user accounts on shared Macs and iOS devices and review who can execute code on them. Use MDM or endpoint inventory to confirm fleet-wide patch levels against these minimum versions.

Affected
Apple iPhone OS (iOS)versions prior to iOS 13.6
Apple iPadOSversions prior to iPadOS 13.6
Apple macOS (macOS Catalina)macOS Catalina versions prior to 10.15.6
Estimated exposure
masshundreds of millions of devices (Apple's active iOS/macOS install base exceeds 1 billion, and all devices on pre-fix builds at disclosure were affected) — Apple's active device fleet numbered well over a billion iOS devices plus a large macOS Catalina population when the July 2020 fixes shipped, so the potentially affected install base is in the hundreds of millions, though most devices have…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.

CISA Known Exploited Vulnerability
Affected
Apple iOS, iPadOS, and macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, mac os x
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news